Skip to content

[AUTO-CHERRYPICK] [AutoPR- Security] Patch libarchive for CVE-2026-15028, CVE-2026-14164, CVE-2026-16517 [HIGH] - branch 3.0-dev - #18280

Closed
azurelinux-ci-jwt-app[bot] wants to merge 1 commit into
3.0-devfrom
cblmargh/cherry-pick-pr-18078-to-3.0-dev
Closed

[AUTO-CHERRYPICK] [AutoPR- Security] Patch libarchive for CVE-2026-15028, CVE-2026-14164, CVE-2026-16517 [HIGH] - branch 3.0-dev#18280
azurelinux-ci-jwt-app[bot] wants to merge 1 commit into
3.0-devfrom
cblmargh/cherry-pick-pr-18078-to-3.0-dev

Conversation

@azurelinux-ci-jwt-app

Copy link
Copy Markdown

This is an auto-generated pull request to cherry-pick commit 83ed843 to 3.0-dev. Original PR: #18078
In case of no merge conflicts, the PR is merged without approval because it's an automated cherry-pick of an already approved PR.
In case of merge conflicts, an AI-based conflict resolver will attempt to resolve conflicts and might make mistakes. The reviewer must check AI's work before approving.

@azurelinux-ci-jwt-app azurelinux-ci-jwt-app Bot added the Auto Fast-track Cherry-pick Automatic cherry-pick from fast-track branch label Jul 31, 2026
@azurelinux-ci-jwt-app

Copy link
Copy Markdown
Author

Auto Cherry-Pick SPEC Validation Summary

libarchive SPEC summary

Source (fasttrack) Target (3.0-dev) Resolved
Version 3.7.7 3.7.7 3.7.7
Release 7 7 7
Patches 15 13 15
Conflict Yes

⚠️ Validation issues:

  • Version-release 3.7.7-7 is not higher than Source 3.7.7-7
  • Version-release 3.7.7-7 is not higher than Target 3.7.7-7
  • Unresolved conflict markers (<<<<<<< / >>>>>>>) found in file
  • Duplicate changelog entry for 3.7.7-7 (appears 2 times)

⚠️ Manual review required — validation found issues that may need correction.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@microsoft-github-policy-service microsoft-github-policy-service Bot added Packaging 3.0-dev PRs Destined for AzureLinux 3.0 labels Jul 31, 2026
…6-16517

The AI-generated cherry-pick left literal <<<<<<< HEAD conflict markers in
libarchive.spec. Rebuild it as a hand-crafted mirror of fasttrack commit
83ed843 so 3.0-dev converges with fasttrack's canonical -7 state:
add Patch13 (CVE-2026-15028) + Patch14 (CVE-2026-16517), consolidate the
existing -7 changelog entry to list all three CVEs. Release stays 7 (no
bump) since fasttrack itself is at -7.

Note: fasttrack subsequently reverted CVE-2026-16517 (#18282) — that will
be delivered by companion PR #18284, keeping 3.0-dev's history as a
faithful mirror of fasttrack's two-step land-then-revert.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 26b18818-c4ef-43b9-ad6c-26bbf7c5259e
@jslobodzian
jslobodzian force-pushed the cblmargh/cherry-pick-pr-18078-to-3.0-dev branch from dc04baf to 40203fc Compare August 1, 2026 04:45
@jslobodzian

Copy link
Copy Markdown
Collaborator

[Toolio Iglesias🗺️] Repushed the branch with a hand-crafted mirror of fasttrack commit 83ed8439ec (the #18078 land).

What was wrong: the auto-cherry-pick left literal <<<<<<< HEAD / ======= / >>>>>>> conflict markers in libarchive.spec, plus 4 unrelated toolchain manifest downgrades (kernel-headers, coreutils, glib, ca-certificates, python3-setuptools, patch, libtool, debugedit) that had nothing to do with libarchive.

What's in the branch now (2 files added, 1 modified):

  • + SPECS/libarchive/CVE-2026-15028.patch
  • + SPECS/libarchive/CVE-2026-16517.patch
  • libarchive.spec: adds Patch13 / Patch14 after existing Patch12, consolidates the 3.7.7-7 changelog entry to list all three CVEs. Release stays at 7 to match fasttrack (no bump).

Sequencing note: fasttrack later reverted just CVE-2026-16517 (#18282). That revert lands via companion PR #18284, which I'll rebuild next. This keeps 3.0-dev history as a faithful mirror of fasttrack's land-then-revert.

jslobodzian added a commit that referenced this pull request Aug 1, 2026
The AI-generated cherry-pick had random line deletions in the CVE-16517
patch delete, a duplicated -5 changelog entry, and a mutated -7 date.
Rebuild it as a clean revert on top of #18280's fixed branch, mirroring
fasttrack commit eb40ad7: drop Patch14, delete CVE-2026-16517.patch,
and trim the -7 changelog line to list just CVE-2026-15028 & CVE-2026-14164.

Once #18280 merges, this PR's diff will naturally shrink to just the
revert (base=3.0-dev).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 26b18818-c4ef-43b9-ad6c-26bbf7c5259e
@jslobodzian

Copy link
Copy Markdown
Collaborator

[Toolio Iglesias🗺️] Closing — superseded by #18284.

Because #18284's branch was built on top of this branch's rebuilt commit (add CVE-2026-15028 + CVE-2026-16517, then revert CVE-2026-16517), merging #18284 alone landed both changes on 3.0-dev in one shot.

Current 3.0-dev tip has libarchive.spec byte-identical to fasttrack/3.0: Release 7, Patch12=CVE-2026-14164, Patch13=CVE-2026-15028, changelog Wed Jul 22 2026 ... -7 - Patch for CVE-2026-15028, CVE-2026-14164. That matches what PMC is publishing (CVE-2026-16517 excluded). Nothing left for this PR to deliver.

@jslobodzian jslobodzian closed this Aug 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3.0-dev PRs Destined for AzureLinux 3.0 Auto Fast-track Cherry-pick Automatic cherry-pick from fast-track branch Packaging

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant